Can someone be fooled into creating a signature for an address that releases funds from that address?
(Or do tx signatures and "ordinary" signatures follow different encoding?)
Im not 100% sure whether they are differently encoded, but my guess is that they are not. The message is just greatly different. Let me give you an example to make this clear. The following is my first raw transaction I created. I had to double spend it later because I did not pay a fee, so you cant find it on the blockchain. It was an attempt to fuse several spam TX into a single input. The TX is signed in its raw form and if you change a single bit the signature is invalid. Thus you cant have part of the message be a hidden transaction. You would need to convince someone to sign a very specific hex string like the "raw" below that makes little sense to a human. Additionally a TX might (as is the case here) need more than one signature.
formatted:
"[
{\"txid\":\"0c6c7de8c27a6bfe5c2e5e9a364bdbd2028194e25ba645bab91eae5668db10fa\",\"vout\":23},
{\"txid\":\"28d39206e2592bf02777831d839baa540137287936a3ee3f2b935bcccf7d2ee0\",\"vout\":4},
{\"txid\":\"4549b62fa61b0612ef6f06413b66d31cb454bfdccb2a12a2ca06e8e0a36c07b5\",\"vout\":1},
{\"txid\":\"cdd2d34071d548455d0b55130472006de2c048452ab96880e63feec619909797\",\"vout\":0}
]"
"{\"1MpNbGQrignRG9QKGbEQpz5uCg8KBJrQ9a\":0.0022}"
raw:
0100000004fa10db6856ae1eb9ba45a65be2948102d2db4b369a5e2e5cfe6b7ac2e87d6c0c1700000000ffffffffe02e7dcfcc5b932b3feea3367928370154aa9b831d837727f02b59e20692d3280400000000ffffffffb5076ca3e0e806caa2122acbdcbf54b41cd3663b41066fef12061ba62fb649450100000000ffffffff97979019c6ee3fe68068b92a4548c0e26d00720413550b5d4548d57140d3d2cd0000000000ffffffff01605b0300000000001976a914e45816c635fd7bfb567aa83c3980066c8de9046988ac00000000
and signed:
0100000004fa10db6856ae1eb9ba45a65be2948102d2db4b369a5e2e5cfe6b7ac2e87d6c0c170000006a4730440220346b1eb415ff87e4e68caee5fb3fe9ac858a12740da5022ab095f86c1faccd17022031b302b383a5f3b70aa7595bf4f66f4a0170449f35081ba631f898a70c5c706d0121024edda80c8cc0d3e10be680e4734279036787c910962925b9f0eedcdbdeb5f7d9ffffffffe02e7dcfcc5b932b3feea3367928370154aa9b831d837727f02b59e20692d328040000006b483045022100d9edc2ebef269df69c016c901d91b5338ed5d97a87e5c0b928b09f7bf1b051f302202cc5a8695cf7f1f597998b735f5339daad228674c4f28b9c55ff8c645509348f0121024edda80c8cc0d3e10be680e4734279036787c910962925b9f0eedcdbdeb5f7d9ffffffffb5076ca3e0e806caa2122acbdcbf54b41cd3663b41066fef12061ba62fb64945010000006b483045022100ef4c065d154113139e8b77a1a2921bb605e469a6085930a86d9f75bb5ce6075e02200caf8c68d41ff2ce7eca3bdc48acd4428e29a2474e063f8e3d6c578a2857d0900121024edda80c8cc0d3e10be680e4734279036787c910962925b9f0eedcdbdeb5f7d9ffffffff97979019c6ee3fe68068b92a4548c0e26d00720413550b5d4548d57140d3d2cd000000006a47304402206378d15f0d751a7c2e87c49a4549d67f0f1302a4dceb91250afdcb4ee725bdb8022023948a95f75289a33b62fe20f9ffa9f1222aa45dc4dd3c046c22b8f4c5e162ba0121024edda80c8cc0d3e10be680e4734279036787c910962925b9f0eedcdbdeb5f7d9ffffffff01605b0300000000001976a914e45816c635fd7bfb567aa83c3980066c8de9046988ac00000000